Senior Application Security Architect

Scalable
Summary
Join Scalable Capital as an Application Security Architect and contribute to embedding security into all phases of the SDLC. Collaborate with development teams, implement secure coding practices, perform threat modeling, and ensure application resilience against security threats. Stay updated on emerging security threats and technologies to enhance the organization's security posture. Develop and implement security architectures, conduct threat modeling, perform code and design reviews, and integrate security practices into the SDLC. Work with cross-functional teams, develop and maintain application security standards, evaluate and manage security tools, participate in incident response, and provide training and guidance to development teams.
Requirements
- Bachelor's or Master's degree in Computer Science, Information Security, or a related field
- Minimum of 5 years in application security, software development, or related roles
- Proven experience with secure coding practices, security assessments, authentication/authorisation design, cryptography, API protection and integrating security into the SDLC
- Proven record of facilitating threat-modelling and delivering risk-balanced solutions to engineering teams
- Experience integrating and tuning security-testing tools in CI/CD workflows
- Strong understanding of application security frameworks and standards (e.g., OWASP ASVS, SAMM, NIST)
- Proficiency in programming languages such as Java, Kotlin, or Python
- Exoerience with cloud security principles and securing applications in cloud environments (AWS in particular)
- Clear, persuasive communication skills for both technical and non-technical audiences
- Ability to work independently and manage multiple projects simultaneously
Responsibilities
- Develop and implement security architectures for applications, ensuring alignment with organizational security policies and compliance requirements
- Conduct threat modeling exercises to identify potential security vulnerabilities and recommend mitigation strategies
- Perform in-depth code and design reviews, delivering actionable remediation guidance
- Integrate security practices into the SDLC, including code reviews, static and dynamic analysis, and security testing
- Work closely with cross-functional teams, including developers, QA, and operations, to ensure security is considered at every stage of application development
- Develop and maintain application security standards, guidelines, and best practices
- Evaluate, implement, and manage application security tools such as SAST, DAST, and IAST solutions
- Participate in incident response activities related to application security breaches, including root cause analysis and remediation planning
- Provide training and guidance to development teams on secure coding practices and emerging security threats
Benefits
- Work from our centrally located offices in the heart of Munich or Berlin, nestled in lively neighborhoods filled with vibrant restaurants, cozy cafés, and a wide range of convenient amenities or choose to work remotely within Germany (if eligible for the job)
- Be productive with the latest hardware and tools
- Learn and grow by joining our in-house knowledge sharing sessions and spending your individual Education Budget
- Learn and experience German culture first hand by joining our free German language classes
- (International) relocation support
- Flexible vacation policy and the opportunity to work from abroad
- Benefit from an attractive compensation package and from the company pension scheme
- Monthly contribution of 25% for the ‘Deutschland Jobticket’
- Say goodbye to order commissions and say hello to your complimentary subscription of Scalable Capital's PRIME+ Broker